Skip to content

fix: settle 0.x memory hardening and security backlog - #139

Merged
codegiveness merged 2 commits into
mainfrom
fix/settle-backlog-0x
Oct 2, 2026
Merged

codegiveness merged 2 commits into
mainfrom
fix/settle-backlog-0x

Conversation

@codegiveness

Copy link
Copy Markdown
Owner

Authorized scope

Maintainer requests reachable PR/issue and security/quality settlement, explicitly continuing 0.x only. No 1.x release is authorized. Oh My Pi/OpenCode production success is recorded as user-reported evidence, not invented 30-day or other-harness certification.

Fixes #55
Fixes #56
Fixes #52

Implementation

Observed local acceptance

  • Build: zero warnings/errors. Unit run: 439 passed, 0 failed, 4 pre-existing unreachable-case skips.
  • Full opt-in run against disposable SQL Server: 464 passed, 0 failed, the same 4 skips; actual integration tests now run. No production database was used.
  • Formatting and actual C# LSP diagnostics: zero errors; the nonshipping fuzz project was separately loaded and checked.
  • CLI validate/help/unknown argument; official MCP Inspector handshake, 9 tools, live list_databases, idempotency annotations: pass.
  • Real MCP reader boundaries, null/Unicode accounting, disabled caps, raw XML refusal/recovery and usable subsequent session: pass. Published trimmed linux-x64 binary and built Alpine container actually queried SQL Server.
  • Locked restore/publish of all six runtime profiles and NuGet pack: pass. Other OS builds were cross-published, not executed.
  • Actual fresh offline npm main/native installs resolved matching 0.5.5 local archives and ran the built binary. Main-only/no-download install produced expected exit 1 and actionable alternatives.
  • Release/version suites, README snippets/badge URLs, npm smoke and behavioral security regressions, actionlint workflow schema: pass.
  • Actual managed crash-detection probe: detected separately. Real 10-second fuzz campaign: 52,661 inputs/11 seconds, feature count 3,191→14,456, corpus 4→867, 0 real findings. This is bounded evidence, not exhaustive security proof.

Settlement gate

Inspect the hosted CI, CodeQL and fuzz executions before merge; inspect Scorecard on merged main before any alert disposition. Then close the six original dependency PRs as incorporated/superseded by this PR, with evidence links. Remaining genuine human/external prerequisites stay visible. Details: docs/security-quality-follow-up.md.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@codegiveness

Copy link
Copy Markdown
Owner Author

Verification evidence is now committed in docs/security-quality-follow-up.md and the corrected draft assessment. Original-head hosted CI, C#/JS CodeQL and fuzz all passed; uploaded CodeQL records had 0 results and empty errors/warnings (C# resolved 283 references, unresolved 0). Downloaded hosted fuzz artifacts show 370,328 inputs in 61 seconds, features 3,191→22,137, corpus 4→1,706; the separate crash probe succeeded and no genuine campaign findings were emitted. Isolated merged Core/Tools coverage measured 85.37% line / 73.69% branch, not whole-repository coverage. After the documentation update, local unit/live-SQL acceptance passed again: 439 / 464 successful tests, 0 failures, four existing skips; CLI validation, format, npm/readme/version checks and the official MCP stdio smoke passed. Waiting for the latest-head checks before merge, then inspecting fresh main Scorecard before alert disposition. External badge review/submission remains #140; independent human review and maintenance history are not fabricated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants